Vulnerabilities

Recent vulnerabilities

Recent vulnerabilities from
Select from 81 available sources using the dropdown above.

CSAF Microsoft 🪟

Recent vulnerabilities · 21271 entries
ID Description Published Updated
msrc_cve-2026-69896 Windows Error Reporting Elevation of Privilege Vulnerability 2026-09-08T07:00:00.000Z 2026-10-13T07:00:00.000Z
msrc_cve-2026-37236 grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the request method is rewritten to an arbitrary attacker-supplied value before routing. This allows bypassing method-based access controls enforced by upstream proxies or WAFs. 2026-09-02T01:04:47.000Z 2026-10-02T04:12:52.000Z
msrc_cve-2026-74531 Bluetooth: hci_conn: hold conn reference in abort_conn_sync() 2026-08-23T14:45:07.000Z 2026-10-02T04:12:01.000Z
msrc_cve-2026-74525 net: sxgbe: free TX rings on RX allocation failure 2026-08-23T14:44:37.000Z 2026-10-02T04:11:38.000Z
msrc_cve-2026-74556 scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer 2026-08-23T14:44:23.000Z 2026-10-02T04:11:15.000Z
msrc_cve-2026-74457 can: peak_usb: add bounds check for USB channel index 2026-08-23T14:44:05.000Z 2026-10-02T04:10:52.000Z
msrc_cve-2026-74454 drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size 2026-08-23T14:42:27.000Z 2026-10-02T04:10:29.000Z
msrc_cve-2026-18743 Popt-devel: popt-static: short realloc in poptconfigfiletostring 2026-09-02T01:02:56.000Z 2026-10-02T04:10:09.000Z
msrc_cve-2026-74479 net: pktgen: fix proc entry use-after-free 2026-08-23T15:04:54.000Z 2026-10-02T04:10:04.000Z
msrc_cve-2026-74516 KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active 2026-08-23T15:04:41.000Z 2026-10-02T04:09:30.000Z
msrc_cve-2026-90388 iommu/dma: Check atomic pool allocation result directly 2026-09-19T01:18:24.000Z 2026-10-02T04:09:02.000Z
msrc_cve-2026-80994 net: openvswitch: fix flow mask use-after-free on flow deletion 2026-09-13T01:08:06.000Z 2026-10-02T04:08:53.000Z
msrc_cve-2026-89894 media: cx231xx: reject geometry changes while the VBI queue is busy 2026-09-17T01:04:50.000Z 2026-10-02T04:08:45.000Z
msrc_cve-2026-74661 mac802154: fix netdev use-after-free in beacon worker 2026-08-24T01:09:31.000Z 2026-10-02T04:08:36.000Z
msrc_cve-2026-74461 i2c: imx: Cancel hrtimer before clearing slave pointer 2026-08-23T15:04:35.000Z 2026-10-02T04:08:32.000Z
msrc_cve-2026-89821 drm/amd/display: avoid divide-by-zero in __is_lut_linear() 2026-09-17T01:04:40.000Z 2026-10-02T04:07:21.000Z
msrc_cve-2026-74682 ALSA: usb-audio: fix OOB write on Type II inbound URBs 2026-08-24T01:09:18.000Z 2026-10-02T04:07:20.000Z
msrc_cve-2026-74455 can: peak_usb: validate uCAN receive record lengths 2026-08-23T15:04:28.000Z 2026-10-02T04:07:19.000Z
msrc_cve-2026-90169 ksmbd: free preauth sessions on connection teardown 2026-09-19T01:09:19.000Z 2026-10-02T04:07:17.000Z
msrc_cve-2026-89947 clk: meson: align gxbb_32k_clk_sel number of parents with actual count 2026-09-17T01:04:29.000Z 2026-10-02T04:06:19.000Z
msrc_cve-2026-90170 ksmbd: validate ipc response length before dereferencing its fields 2026-09-19T01:17:57.000Z 2026-10-02T04:06:03.000Z
msrc_cve-2026-90092 Bluetooth: L2CAP: reject accept queue add unless BT_LISTEN 2026-09-19T01:20:22.000Z 2026-10-02T04:05:42.000Z
msrc_cve-2026-74613 vsock/virtio: avoid refilling the RX queue after teardown 2026-08-24T01:09:12.000Z 2026-10-02T04:05:42.000Z
msrc_cve-2026-74572 btrfs: zoned: fix deadlock between metadata writeback and transaction commit 2026-08-23T15:04:22.000Z 2026-10-02T04:05:24.000Z
msrc_cve-2026-92494 ext4: fix buffer_head leak in ext4_init_orphan_info 2026-09-19T01:09:05.000Z 2026-10-02T04:05:19.000Z
msrc_cve-2026-89922 KVM: s390: Take srcu when importing watchpoint data 2026-09-17T01:04:19.000Z 2026-10-02T04:05:03.000Z
msrc_cve-2026-93048 mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() 2026-09-19T01:17:45.000Z 2026-10-02T04:04:42.000Z
msrc_cve-2026-74700 net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers 2026-08-24T01:08:53.000Z 2026-10-02T04:04:26.000Z
msrc_cve-2026-89540 sunrpc: init gssp_lock before publishing proc entry 2026-09-13T01:06:53.000Z 2026-10-02T04:04:12.000Z
msrc_cve-2026-74567 keys: fix out-of-bounds read in keyring_get_key_chunk() 2026-08-23T15:04:01.000Z 2026-10-02T04:04:04.000Z